CVE-2005-1233
PHP Labs proFile - Cross-Site Scripting via dir or file Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-1233. PoCs published by sNKenjoi.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in PHP Labs proFile, where malicious script code can be embedded in the 'file' parameter of specific actions (delete, copy, rename). This allows attackers to steal cookies or perform other client-side attacks.
Description
Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in PHP Labs proFile, where malicious script code can be embedded in the 'file' parameter of specific actions (delete, copy, rename). This allows attackers to steal cookies or perform other client-side attacks.
The provided text describes a cross-site scripting (XSS) vulnerability in PHP Labs proFile, where an attacker can inject malicious script code via the 'dir' parameter in the URL. This can lead to theft of authentication credentials or other client-side attacks.